How work ships
Staging topology
Exo owns staging for Apps; Construct owns staging for Pages. Review routes follow ownership, not production hostnames.
Source: Exo staging topology.
Canonical routes
| Resource | Canonical staging route | Example |
|---|---|---|
| Exo platform | https://staging.exo.now | The Exo control plane |
| App | https://staging.exo.now/{app} | https://staging.exo.now/rampart |
| Construct Page | https://staging.construct.page/{page} | https://staging.construct.page/dan |
Construct is an App, so it stages at staging.exo.now/construct. It is also the Page platform,
so the Pages it manages stage on staging.construct.page.
Routing and authorization
The canonical route is a gateway address. A provider-generated hostname is an operational coordinate and a source of deployment evidence, never the review URL.
- The shared origin authenticates the session.
- The gateway resolves the first path segment to a declared App or Construct Page.
- The server validates an active, environment-specific Exo grant for that resource.
- The gateway forwards only to the declared provider target and keeps the canonical browser URL.
Apps share one non-production identity plane without every signed-in user getting access to every App. Health checks and signed webhooks keep narrow, documented exceptions.
Identity provider in the source doc
The topology doc still names Clerk as the authenticator for the shared staging origin. Exo Key (ADR 0004) is replacing Clerk App by App. Which Apps have switched is tracked in the Exo Key guide.
Adoption inventory
The last verified observations recorded in the topology doc:
| Resource | Route | Status |
|---|---|---|
| Exo | staging.exo.now | Verified live |
| Construct | staging.exo.now/construct | Verified live (Construct commit 875ac2e) |
| Rampart | staging.exo.now/rampart | Verified live; removal of staging.rampart.fit is a separate domain action |
| Observatory | staging.exo.now/observatory | Verified live |
| Cosmograph | staging.exo.now/cosmograph | Verified live |
| Vector | staging.exo.now/vector | Provisioning required |
| Universe | staging.exo.now/universe | Provisioning required |
| Dropship | staging.exo.now/dropship | Verified live |
| Construct-managed sites | staging.construct.page/{page} | Per-Page migration |
A route is never marked live from configuration alone. It needs provider health, exact-commit evidence, and a browser pass.
Per-resource migration checklist
- Classify the resource as
platform,app, orconstruct-page, and reserve its slug. - Record the current provider service, source branch, provider URL, and verified commit.
- Configure gateway routing for the target path without changing Production.
- Configure the non-production authorized origin and the resource-specific Exo grant.
- Verify unauthenticated denial, authorized success, cross-resource denial, return paths, health, noindex headers, and the exact deployed commit.
- Review the canonical URL in a browser.
- Remove the old app-domain staging route, or make it redirect-only.
- Attach evidence to the Exo work and release records.